主题:【注意】关于西西河断线5-6小时的简要说明,及其他,请各位关注 -- 铁手
Did they provide details? I remember you set proc/thread limit = 500 on apache. Hard to believe on only 500 procs would take down all procs. For DOS, it will be idling connection, which should not take out DNS normally. Might be somethin I don't know.
1. ask for a separate DNS server. cchere already host several websites. Having DNS on same machine will be too easy for DOS. DNS server is normally shared, so it should be free.
2. If this is really DDOS, you have very little choice w/o the help from their isp. Right now it does not appear to be that bad. If it gets worse, you would have to choose b/w blocking innocent people vs. not serving the majority -- people who wants to come can still use proxy to access cchere.
You would want to do IP filtering as early as possible, ideally on the incoming firewall. Host.deny is a little late. Those firewall/router hardware supports off-the-wire classification. This means server does not even see the incoming connection request.
- 相关回复 上下关系8
What did the last portion of Apache log say? 1 虹道 字698 2006-03-16 00:16:50
可以考虑把IP段贴出来 子虚乌有 字94 2006-03-14 02:44:59
我建议还是慎重 孔雀王 字260 2006-03-13 22:39:24
Difficult problem
可能是偶然? zzhong 字290 2006-03-13 19:37:39
嗯。有误解。不是铁通对西西河怎样。 铁手 字96 2006-03-13 20:45:12
老大消火,兄弟们也很气愤;一天不能上西西河,心里这个难受哟 盟军敢死队 字0 2006-03-13 18:05:03
花安慰一下铁老大,我正觉得奇怪呢。 重庆老牛 字0 2006-03-13 18:04:19